threat-intel
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
High
Summary
A new typosquatting campaign targeting RubyGems users has been identified, leveraging a Rust-based stealer to steal browser credentials, cryptocurrency wallets, and Telegram data. The campaign utilizes a 'StubMaker' tool that generates a fake build toolchain to conceal a malicious install, and exploits a vulnerability in Ruby's package naming system to revive previously yanked malicious gems. The attack chain involves a GitHub-hosted Rust loader that launches a Go-based stealer, collecting data from Chromium-based browsers and other sources.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
